Okta SCIM
Configure Native SCIM 2.0 provisioning in Okta so that platform accounts are created, updated and disabled automatically as assignments change.
This guide guides you through setting the native SCIM provisioning from Okta to automatically sync users on the platform.
Prerequisites
Section entitled ‘Prerequisites’- Okta administrator access
- the platform organization administrator access
- An Octa plan that supports Provisioning SCIM (Octa Life Cycle Management)
How It Works
Posts Tagged ‘how it works’In native mode, Okta pushes user changes to the real-time SCIM 2.0 endpoint of the platform. When you assign users or groups to the platform application in Okta, it:
- Creates Platform accounts for newly allocated users
- Updates user attributes when changing to Okta
- Deactivates Platform accounts when users are not assigned or deactivated
- Deletes Platform accounts when users are permanently removed (if they are configured)
Mapped Attributes
Title: Mapped Attributes| Okta User Profile Field | SCIM Attribute | Notes |
|---|---|---|
| userName | userName |
Required, unique |
| displayName | displayName |
|
| givenName | name.givenName |
|
| familyName | name.familyName |
|
| nickName | nickName |
|
| active | active |
|
emails[type eq "work"].value |
Multi-valued | |
| primaryPhone | phoneNumbers[type eq "work"].value |
Multi-valued |
| title | title |
|
| userType | userType |
|
| preferredLanguage | preferredLanguage |
|
| locale | locale |
|
| timezone | timezone |
|
| profileUrl | profileUrl |
Enterprise User Extension attributes:
| Okta User Profile Field | SCIM Attribute |
|---|---|
| employeeNumber | enterprise:employeeNumber |
| organization | enterprise:organization |
| department | enterprise:department |
| division | enterprise:division |
| costCenter | enterprise:costCenter |
| manager | enterprise:manager.value |
Step 1: Generate SCIM Credentials in the platform
Step 1: Generate SCIM Credentials in the platform-
Log in to the platform as an organization administrator
-
Go to Organization Settings > Authentication > Auto-Provisioning
-
Click Add Connector and select SCIM
-
Copy the SCIM Endpoint URL and Bearer Token
Step 2: Create a SCIM Application in Okta
Step 2: Create a SCIM Application in Okta-
Sign up to you. Okta Admin Console
-
Go to Applications > Applications
-
Click Browse App Catalog
-
Search for SCIM 2.0 Test App (Header Auth) and select it
-
Click Add Integration
-
Enter the following:
Field Value Application label Probo -
Click Next, then Done
Step 3: Configure Provisioning
Section entitled “Step 3: Configure Provisioning”-
In the platform application, go to Provisioning tab
-
Click Configure API Integration
-
Check Enable API Integration
-
Enter the following:
Field Value SCIM 2.0 Base URL The SCIM endpoint URL (e.g. https://your-probo-domain.com/api/connect/v1/scim/2.0)OAuth Bearer Token The Token of the Carrier in Step 1 -
Click Test API Credentials to check Okta can reach the SCIM platform
-
Click Save
Step 4: Enable Provisioning Actions
Step 4: Enable Provisioning Actions-
In the Provisioning tab, click To App in the left sidebar
-
Click Edit
-
Enable the following provisioning actions:
Action Setting Create Users ☑️ Enabled Update User Attributes ☑️ Enabled Deactivate Users ☑️ Enabled -
Click Save
Step 5: Configure Attribute Mappings
Step 5: Configure Attribute MappingsDefault attribute mappings work for most settings. To review or customize them:
- In the Provisioning tab, scroll to Attribute Mappings
- Mapping review – Okta user profile attributes of the default map for SCIM attributes supported by the platform
- Adjust maps if necessary (e.g. maps
employeeNumbertourn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber) - Click Save
Step 6: Assign Users and Groups
Step 6: Assign Users and Groups- In the platform application, go to Assignments tab
- Click Assign > Assign to People or Assign to Groups
- Select the users or groups you want to provide to the platform
- Click Assign, then Save and Go Back
- Click Done
Only assigned users (or members of assigned groups) will be provided. This gives you fine control over who receives a platform account.
Membership roles of the platform are allocated to People or mapped with SAML Role Attribute. SCIM creates people as Employee The job title (title) and user type (userType) are synchronized as the profile context for access assessments, not as a member role.
Step 7: Verify Provisioning
Section “Step 7: Verify Provisioning”- In Okta, go to the platform app > Provisioning tab > To App to check provisioning status
- Go to Reports > System Log and filter by application to see delivery events
- On the platform, go to People to verify users have been provisioned
- Check Organization Settings > Authentication > Auto-Provisioning > Event Log for detailed SCIM events
Troubleshooting
Section “Troubleshooting”Test API Credentials Fails
Section titled “APICredentials Fails”- CauseThe SCIM endpoint URL or carrier token is incorrect or a firewall blocks the connection
- SolutionCheck the endpoint URL that includes the entire route (which ends in
/scim/2.0). Re-generate the carrier token in the platform if necessary. Make sure your network allows HTTPS output from Okta to your platform instance.
Users Not Being Provisioned
Section “Users Not Being Provisioned”- CauseUsers or groups are not assigned to the app or provision actions are not enabled
- Solution: Check whether users are assigned to the Assignments The camp and that. Create Users is enabled under Provisioning > To App
Provisioning Errors in Logs
Section “Provisioning Errors in Logs”- Cause: Attribute mapping conflicts or missing required attributes
- Solution: Check the System Log In Okta for specific error messages. Make sure that
userNameis mapped to a single value, which is not empty (usually the user's email)
Users Not Deactivated After Removal
“Users Not Deactivated After Removal”- Cause: Octa may continue to process the modification or Deactivate Users is not enabled
- Solution: Verify that Deactivate Users is enabled under Provisioning > To AppCheck the system log for the deprovisioning event. For immediate effect, manually trigger a push by clicking on Push Now in the application’s provisioning settings.
Duplicate Users
Section titled “Duplicate Users”- Cause:
userNamein Okta does not match an existing platform user email - Solution: Make sure that the attribute mapped at
userNamematches the email format used on the platform.
Combining with SSO
Section entitled ‘Combining with SSO’For the best experience, combine SCIM provisioning with SAML SSO:
- SCIM provisioning user life cycle management – automatic creation and deactivation of accounts
- SAML SSO deals with authentication – users log in with their Okta credentials
This means that users automatically get platform accounts when they join your organization and lose access when they leave, without the need for manual account management.